VDB
CVE-2026-22718
CVE-2026-22718
PUBLISHED
On March 19, 2026, Spring published security advisories to address vulnerabilities in the following products. Included was a critical update for the following: Spring Boot – multiple versions Spring Security – multiple versions The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.
EPSS 0.05% · 16.4th percentile
Risk Scores
EPSS Score
0.05%
16.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| VMware | Spring Security – multiple versions | |
| VMware | Spring Boot – multiple versions |
Exploit Intelligence
- https://spring.io/security/cve-2026-22731 (circl)
- CIRCL seen: CVE-2026-22718 (circl-sighting)
- CIRCL seen: CVE-2026-22718 (circl-sighting)
- CIRCL seen: CVE-2026-22718 (circl-sighting)
- CIRCL seen: CVE-2026-22718 (circl-sighting)
- https://spring.io/security/cve-2026-22718 (circl)
- CIRCL seen: CVE-2026-22731 (circl-sighting)
- CIRCL seen: CVE-2026-22731 (circl-sighting)
- CIRCL seen: CVE-2026-22731 (circl-sighting)
Timeline
- Jan 9, 2026 CVE ID Reserved
- Jan 14, 2026 EPSS Score
- Jan 14, 2026 CVE Published
- Jan 14, 2026 PoC Published
- Jan 14, 2026 PoC Published
- Jan 14, 2026 CVE Updated
- Jan 15, 2026 PoC Published
- Jan 17, 2026 EPSS Score
- Jan 20, 2026 EPSS Score
- Jan 23, 2026 EPSS Score
- Jan 26, 2026 EPSS Score
- Jan 29, 2026 EPSS Score